SaltStack Salt authentication bypass (CVE-2020-11651) — part of the batch listed the day the catalog opened, with 181 days allowed
A flaw at the center of a system that pushes configuration to many servers at once, where some functions can be reached without authentication. It belongs to the batch listed on the day the catalog opened, with about half a year allowed, and its description carries an unusual line saying that users following basic practice are unaffected.
Key facts
- CVE IDCVE-2020-11651
- Affected (vendor / product)SaltStack Salt
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2022-05-03 (U.S. federal civilian agencies, BOD 22-01)
Key points
- A flaw at the center of a configuration distribution system, where calls are not validated properly and some functions are reachable without authentication.
- It is described as usable to obtain tokens held at the center or to run commands on the machines below.
- It belongs to the bulk listing of 3 November 2021 and carries an allowance of 181 days, shared by 238 of the 1,694 records this site holds as of 2026-09-04.
- The description closes with an unusual line placing users who follow fundamental guidance and established practice outside its scope.
- No weakness classification is recorded for this entry, as with 175 (10.3%) of those same 1,694 records.
1Standing where distribution happens
Salt exists to push configuration and commands out to many servers at once. A central component sends instructions to the receivers running on each machine. As the catalog describes it, part of that center does not validate calls properly, and some functions can be reached without authenticating. What is reachable includes user tokens and a means of running commands on the machines below.
A system built to distribute is valuable because it can reach everywhere, and once taken, its reach is the same reach.
2A layer created by the first listing
- 1The catalog opensOn 3 November 2021 a large number of entries are listed together
- 2The allowanceDeadlines for that layer are set about half a year out, at 181 days
- 3AfterwardsEntries added individually settle on 21 days as the standard
- 4TodayOf the 1,694 records this site holds as of 2026-09-04, 238 carry an allowance of 181 days
The 181 days here is neither punishment nor leniency; it comes from the bulk listing that opened the catalog. Once operation settled into routine, 21 days became standard, a value shared by 1,025 entries. Read the number alone and this looks like a mild entry granted half a year. The meaning of a deadline does not come through until you check when the entry was listed.
3An unusual line in the description
This description ends by saying that users who follow fundamental guidelines and best practices are not affected. Catalog descriptions normally state what can happen and stop there. Conditionally denying impact is rare, and read the other way it suggests the flaw bites where the center has been placed somewhere reachable. The catalog does not spell out that condition.
4Sometimes the classification is simply absent
No weakness classification is recorded for this entry. Among those same 1,694 records, 175 (10.3%) are the same. Without a classification there is no way to search sideways for the same kind of weakness, and each case has to be handled on its own. Confirmed exploitation can settle first and classification arrive later. Being listed and being organized are different things.
Why it matters
A system built to push configuration everywhere has a compromise radius equal to its reach. The privilege held at such a center and how little it is thought about are rarely in proportion. Deadlines, too, have to be read together with when an entry was listed: the same catalog means different things for the opening batch and for routine operation.
FAQ
Why is the allowance 181 days?
Are basic precautions enough?
Why is there no classification?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).